Описание
Security update for pgadmin4
This update for pgadmin4 fixes the following issues:
- CVE-2024-4216: Fixed XSS in /settings/store endpoint (bsc#1223868)
Список пакетов
SUSE Linux Enterprise Module for Python 3 15 SP6
pgadmin4-4.30-150300.3.15.1
pgadmin4-doc-4.30-150300.3.15.1
pgadmin4-web-4.30-150300.3.15.1
SUSE Linux Enterprise Module for Server Applications 15 SP5
pgadmin4-4.30-150300.3.15.1
pgadmin4-doc-4.30-150300.3.15.1
pgadmin4-web-4.30-150300.3.15.1
openSUSE Leap 15.5
pgadmin4-4.30-150300.3.15.1
pgadmin4-doc-4.30-150300.3.15.1
pgadmin4-web-4.30-150300.3.15.1
pgadmin4-web-uwsgi-4.30-150300.3.15.1
Ссылки
- Link for SUSE-SU-2024:3552-1
- E-Mail link for SUSE-SU-2024:3552-1
- SUSE Security Ratings
- SUSE Bug 1223868
- SUSE CVE CVE-2024-4216 page
Описание
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
Затронутые продукты
SUSE Linux Enterprise Module for Python 3 15 SP6:pgadmin4-4.30-150300.3.15.1
SUSE Linux Enterprise Module for Python 3 15 SP6:pgadmin4-doc-4.30-150300.3.15.1
SUSE Linux Enterprise Module for Python 3 15 SP6:pgadmin4-web-4.30-150300.3.15.1
SUSE Linux Enterprise Module for Server Applications 15 SP5:pgadmin4-4.30-150300.3.15.1
Ссылки
- CVE-2024-4216
- SUSE Bug 1223868